A revisit of remote Spectre attacks on Cloudflare Workers
Blog post from Cloudflare
Cloudflare reassessed remote Spectre risks in its Workers platform after advances in attack-stabilization techniques and discovered that a limitation in its Dynamic Process Isolation (DyPrIs) defense enabled a controlled end-to-end cross-tenant memory-leak demonstration in production. Researchers overcame frozen local timers, shared-resource noise, cache-eviction challenges, and execution limits by combining speculative type-confusion gadgets, cache-state amplification using the L1 cache’s PLRU policy, remote WebSocket-based timing, co-location through Worker subrequests, and persistent Durable Objects. The proof of concept leaked a deliberately planted JWT token from a co-located Worker at up to 12 bits per second with more than 99% accuracy, substantially faster than an earlier attack, although Cloudflare found no evidence of exploitation. The attack avoided DyPrIs detection because isolation occurred only after invocation completion and I/O-heavy WebSocket activity distorted its hardware-counter detection metrics. Cloudflare reports that the issue has already been mitigated through improvements to DyPrIs, deployment of the V8 memory sandbox, and hardware-assisted in-process isolation using Memory Protection Keys, which creates stronger boundaries between isolate heaps while not fully eliminating the broader class of Spectre-related risks.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Real-time | 1 | 4,432 | 1,050 | 222 | -31% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.